live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
analysisAI

IBM turns Maximo workflows into approval-gated MCP tools

A tested OpenShift walkthrough shows how Maximo Manage can expose an existing workflow to an AI agent, while surfacing sharp support and response-design caveats.

Maximo workflow tool on OpenShift with approval gate and record lookup.
AI-generated diagram
By The News Desk· Oct 10, 2026the quick take — two AI hosts go live when you do

IBM has documented a concrete pattern for connecting AI agents to governed business processes: publish an active Maximo Manage workflow as a Model Context Protocol tool, then let the agent invoke it on a specific record. The walkthrough was built and tested with Maximo Application Suite 9.2.7, Manage 9.2.4 and AI Service 9.2 on Red Hat OpenShift.

What the pattern does

In the example, an existing work-order review process becomes a tool named wf_test_wf_1. Maximo supplies the tool schema rather than requiring a custom script: every workflow tool accepts an href that identifies the target record. The workflow description becomes the description an MCP client uses when deciding whether the tool fits a request.

The guide shows the full chain from a natural-language request to execution. The agent first finds the work order and obtains its record reference. Because the tool is marked as changing data, the Assistant pauses for approval. After approval, Maximo starts the workflow as the calling user, creates an active workflow instance and places the review task in the user’s inbox.

That is more useful than a generic “agent calls an API” example. It preserves the workflow’s assignments, approval path and record permissions while making the process available through an MCP interface.

The two caveats that matter

The first issue is the response. A workflow tool can return an empty object even when it succeeds. In IBM’s test, the model interpreted that empty response as if no information had been found, although the workflow had started. The guide fixes this by attaching an object structure and query template so the tool returns the updated record. Teams testing similar tools should verify both the back-end state change and the agent’s final message.

The second issue is supportability. On the tested Maximo version, the Assistant filtered out the WFPROCESS tool type by default. The author added it to an agent allow list in a lab, but explicitly says that was not a documented or supported setting and could be overwritten by the operator. The MCP server still exposes the tool to other clients, but production use through the Maximo Assistant requires an IBM-supported enablement path.

What platform teams should take away

The strongest part of the pattern is its separation of responsibilities. Maximo owns the workflow and authorization model; MCP provides discovery and invocation; the agent translates a user request into a record lookup and tool call. Marking the tool as data-changing gives the client enough metadata to insert a human approval step.

Before adopting the pattern, teams should choose workflows whose first action is safe, make descriptions explicit about the resulting change, provide a useful response template, and test duplicate invocation. IBM notes that starting the same process twice on one record fails and that stopping an initiated process must be handled through Workflow Administration.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.